{"id":4623,"date":"2014-02-04T17:00:30","date_gmt":"2014-02-05T01:00:30","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=4623"},"modified":"2020-04-21T14:39:32","modified_gmt":"2020-04-21T21:39:32","slug":"cybersecurity-canon-worm","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2014\/02\/cybersecurity-canon-worm\/","title":{"rendered":"The Cybersecurity Canon: Worm"},"content":{"rendered":"<p><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red.png\"><div style=\"max-width:100%\" data-width=\"500\"><span class=\"ar-custom\" style=\"padding-bottom:43.6%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter size-large wp-image-9648 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-500x218.png\" alt=\"cybersec canon red\" width=\"500\" height=\"218\" srcset=\"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-500x218.png 500w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-230x100.png 230w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-510x223.png 510w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red-91x40.png 91w, https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2015\/07\/cybersec-canon-red.png 786w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/span><\/div><\/a><\/p>\n<p><i>For the past decade, I have had this notion that there must be a <\/i><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/tag\/cybersecurity-canon\/\" target=\"_blank\" rel=\"noopener noreferrer\"><i>Cybersecurity Canon:<\/i><\/a><i> a list of must-read books where the content is timeless, genuinely represents an aspect of the community that is true and precise and that, if not read, leaves a hole in cybersecurity professional\u2019s education. I\u2019ll be presenting on this topic at RSA 2014, and between now and then, <\/i><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2013\/12\/introducing-cybersecurity-canon-books-read\/\" target=\"_blank\" rel=\"noopener noreferrer\"><i>I\u2019d like to discuss a few of my early candidates for inclusion<\/i><\/a><i>. I love a good argument, so feel free to let me know what you think.<\/i><\/p>\n<p><b>Worm: The First Digital World War (2011) <\/b>by Mark Bowden<\/p>\n<p>Worm: The First Digital World War is the story of how the cybersecurity community came together to do battle with what seemed at the time to be the largest and most significant cyber threat to date: the Conficker worm, which was <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2010\/11\/protection-against-conficker\/\" target=\"_blank\" rel=\"noopener noreferrer\">covered frequently by Palo Alto Networks researchers<\/a>, among many others.<!--more--><\/p>\n<p>It was the time of the Estonian and Georgian distributed denial of service (DDoS) attacks, and the Conficker botnet was growing to be the largest DDoS delivery system ever created. A white hat group of cyber \u00fcbergeeks formed the Conficker Cabal to stop the worm because most of the world could not even understand it, let alone do something about it.<\/p>\n<p>Mark Bowden, who wrote Black Hawk Down: A Story of Modern War among other books, accurately captures the essence of our cybersecurity community in times of crisis. He compares us all to cybersecurity superheroes, like the X-Men of Marvel Comics fame, because of what he sees as our superhuman ability to work with computers and our desire to help each other.<\/p>\n<p>Seasoned security professionals will learn nothing new here in terms of technology and craft, but they will remember that time and how we were all very worried about 1 April 2009: the day that the world thought that Conficker would come to life.<\/p>\n<p>I think freshmen security practitioners will get a lot out of this book, however. Bowden does a great job of simply and clearly explaining many of the key technical pieces that make the Internet run. If you\u2019re new to the community, this book makes a great introduction. It is canon-worthy material, and you should have read it by now. (But more importantly, how can you not like a book where the author favorably compares the cybersecurity community to the X-Men? As Stan Lee likes to say, \u201c'Nuff said.\u201d)<\/p>\n<p><b>The History<\/b><\/p>\n<p>When Bowden published Black Hawk Down, I was blown away. In that book, Bowden puts you right in the streets of Mogadishu, Somalia, with the soldiers, rangers, and bad guys who made up that fight. And then, when the 2001 movie came out and was equally as intense, I felt like I had some smidgen of understanding regarding what the U.S. armed forces had to deal with during this specific fight but, more generally, what they have to endure every day when they are deployed to areas like the Middle East.<\/p>\n<p>When I heard that Bowden was taking a stab at the story behind the Conficker worm, I was excited. He is a high-caliber author attempting to describe the geeky details of the cybersecurity community at a key point in our history. I was hoping that he would make what we do in the security community sound as interesting and astonishing as he made the soldiers sound in Black Hawk Down. I think that he accomplishes this task but not in the way that you might think. He succeeds in giving a bird\u2019s-eye view of our community\u2019s collective thinking process. He captures our almost universal and delightful -- if somewhat naive \u2013 belief that we should all help each other out and contrasts that to the relative size of our egos and how self-destructive that can be to a group effort.<\/p>\n<p>As you may recall, <a href=\"http:\/\/www.confickerworkinggroup.org\/wiki\/pmwiki.php\/Main\/HomePage\" target=\"_blank\" rel=\"noopener noreferrer\">Conficker is a worm that started targeting victims<\/a> running the Windows operating system in 2008. For non-techie readers, a worm is a piece of malicious code designed to compromise a computer and then replicate itself automatically through the network to as many computers as it can. Every compromised host belongs to the worm\u2019s collective called, in generic terms, a botnet or a robot network. It is a robot network because the owner of it can direct every machine within the collective to do his or her bidding: deliver spam, decipher encryption, dispatch denial of service attacks, etc.<\/p>\n<p>John Brunner, the author of The Shockwave Rider, <a href=\"https:\/\/www.goodreads.com\/book\/show\/41070.The_Shockwave_Rider?ac=1\" target=\"_blank\" rel=\"noopener noreferrer\">first wrote about the idea of a worm<\/a> in his prescient 1975 novel a full decade before the Internet was more widely talked about. Around the same time, Robert Thomas built the first proof-of-concept worm called Creeper, which was designed to be an experimental mobile program in which the program itself would look around the network to find the best computer to use for its task. It was not until 1988 when the <a href=\"http:\/\/www.washingtonpost.com\/blogs\/the-switch\/wp\/2013\/11\/01\/how-a-grad-student-trying-to-build-the-first-botnet-brought-the-internet-to-its-knees\/\" target=\"_blank\" rel=\"noopener noreferrer\">Morris worm brought the Internet to its knees<\/a> that we all began to understand what a malicious application of a worm might accomplish.<\/p>\n<p>Today, botnets are reusable. Authors send new instructions to their botnets when they want to repurpose them through some sort of command-and-control mechanism. The difference between a virus and a worm is that a virus does not try to spread on its own. Good worms spread very fast. Famous worms in our short Internet history include the Morris worm, Code Red and Slammer.<\/p>\n<p><a href=\"http:\/\/www.giac.org\/paper\/gsec\/3091\/ms-sql-slammer-sapphire-worm\/105136\" target=\"_blank\" rel=\"noopener noreferrer\">In the Slammer case<\/a>, the worm infected 90 percent of the vulnerable computers connected to the Internet within ten minutes of the first infection. Let me restate that again so that you understand the magnitude of that incredible statistic: of the 75,000 machines connected to the Internet that were vulnerable to the attack, the worm compromised 90 percent of them in the first ten minutes after it compromised victim zero. The mind boggles.<\/p>\n<p>Security researches first noticed the Conficker worm at the end of 2008. Microsoft immediately patched the vulnerability in its operating system, but because many of the computer owners who run the Windows operating system do not patch their systems regularly, they were vulnerable to the attack. By the end of 2010, as Bowden explaions, infection rates had grown large enough to pass the Slammer worm infections rates of 2003. Strangely, the botnet owners had not done anything with the system yet. Between 2008 and 2010, the botnet sat idle, growing exponentially but never being used, growing around the same time as other real-world cyber events took place, including the 2007 DDoS attack against Estonia and the 2008 DDoS attack against Georgia.<\/p>\n<p>The community had DDoS attacks on the mind. Prominent individuals in the security community became alarmed that this new threat, this new weapon, this largest denial of service machine ever created, was continuing to grow unabated. Some decided to do something about it. The \u201ccabal,\u201d as it was affectionately referred to by its members and later changed to the Conficker Working Group, had many security luminaries.<\/p>\n<p><b>The Story<\/b><\/p>\n<p>Bowden spools the story out in two threads. The first thread is the description of the punch-counterpunch between the cabal and its adversaries. It\u2019s fascinating and shows how two groups of \u00fcbergeeks\u2014the cabal and the Conficker authors \u2014who understand the Internet and its systems in a way that mere mortals could not comprehend did battle over a two-year stretch in a classic white-hat-versus-black-hat confrontation. Rarely does the public get to see this interchange in the public arena. Other books that cover similar battles are <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2013\/12\/cybersecurity-canon-cuckoos-egg\/\" target=\"_blank\" rel=\"noopener noreferrer\">Clifford Stoll\u2019s The Cuckoo\u2019s Egg<\/a> and <a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2014\/01\/cybersecurity-canon-confront-conceal\/\" target=\"_blank\" rel=\"noopener noreferrer\">David E. Sanger\u2019s Confront and Conceal<\/a>, both of which I\u2019ve already reviewed for the Cybersecurity Canon.<\/p>\n<p>The second thread of the story is about the people working in the cabal. This is where Bowden hits the ball out of the park as an author. He compares the group members to the X-Men, the famous Marvel Comics super hero team with mutant abilities:<\/p>\n<p>\u201cWhat were superheroes, after all, but those with special powers? Marvel\u2019s creations were also invariably outsiders, not just special but mutant, a little bit off, defiantly antisocial, prone to sarcasm and cracking wise, suspicious of authority, both governmental and corporate.\u201d<\/p>\n<p>Bowden describes how most of the cabal members had realized at one time or another that compromising computer systems was pretty easy. That ability was their \u201cmutant superpower.\u201d Most \u201cnormal\u201d people have a hard time simply understanding the computer\u2019s on-off switch. These \u00fcbergeeks did not. And when they were doing their normal day jobs, they assumed the role of the mild-mannered Clark Kent: not intimidating and practically invisible to the rest of the world.<\/p>\n<p>Writes Bowden: \u201cThey went about their day jobs as unassuming techies, men whose conversation was guaranteed to produce the Glaze, but out here in the cyberworld they were nothing less than the Anointed, the Guardians, the Special Ones: not just the ones capable of seeing the threat that no one else could see, but the only ones who could conceivably stop it.\u201d<\/p>\n<p>\u201cThe Glaze.\u201d I love that phrase. I have seen it many times on the faces of my friends and family members when they politely ask me a question about what I do for a living. Sometimes I forget and actually attempt to explain it until I get, as Bowden says, \u201cthe unmistakable look of profound confusion and uninterest that descends whenever a conversation turns to the inner workings of a computer.\u201d<\/p>\n<p>I think my record for achieving \u201cThe Glaze\u201d is less than 10 seconds.<\/p>\n<p><b>The Tech<\/b><\/p>\n<p>To describe the punch-counterpunch of the \u00fcbergeeks, Bowden has to explain a lot of the technical pieces involved in order to make the story compelling, and he has to describe a bit of Internet history so that the reader can understand why the conditions for the Conficker worm were perfect for when they occurred.<\/p>\n<p>Bowden has a knack for taking complex Internet technology and explaining it in a way that even a non-techie can understand. He uses a wonderful analogy comparing a botnet to the Starship Enterprise, explains the Internet by comparing it to human brain function, and describes buffer overflows by demonstrating how a chef reads recipes and cooks food in a kitchen.<\/p>\n<p>He also does a decent job explaining the function of communications ports, why malcode is packed (compression and stealth), the difference between dynamic and static malcode analysis, why bad guys obfuscate their code, and how public key encryption and the Domain Name System (DNS) work.<\/p>\n<p><b>Conclusion<\/b><\/p>\n<p>Bowden\u2019s critics like to deflate the importance of this book because the Conficker authors never used the system to any significance. Well, actually, two weeks after the 1 April 2009 update, the <a href=\"http:\/\/news.softpedia.com\/news\/Facts-and-Figures-on-Conficker-Malware-Infographic-402762.shtml\" target=\"_blank\" rel=\"noopener noreferrer\">Conficker authors rented the botnet to a well-known spammer named Waladec<\/a>, and in June 2011, US and Ukraine law enforcement officials arrested 16 Kiev hackers who used Conficker to steal $73 million from international banking accounts.<\/p>\n<p>However, nobody used the botnet to take down the Internet like the Morris worm did. After the cabal finally succeeded in getting the security community worried about the potential threat, the 1 April deadline came and went with a whimper. The press compared it to the other great nonevent of our Internet history: Y2K. The cabal did not succeed in eradicating the worm from the Internet either. The group stopped it from receiving instructions\u2014check\u2014but they were unable to kill it\u2014no checkmate. At last count, Conficker continues to infect some twenty-four million computers connected to the Internet.<\/p>\n<p>But here\u2019s why I think that criticism is shortsighted. Back then, during the time of the Estonia and Georgia DDoS attacks, we were all still thinking that somebody might try to kill the Internet for some diabolical purpose. That thinking has largely changed since then. Why would bad guys kill the Internet when they need it to accomplish their goals?<\/p>\n<p>Back then, we were all concerned about it. Bowden captures the security community coming together to combat a potential worldwide threat, a threat that few people on the planet could fully understand, let alone do something about. He precisely and, I think, accurately captures the essence of our community, these cyber X-Men with the \u00fcbergeek superpowers who volunteer to combat this threat simply because they can.<\/p>\n<p>For that reason alone, the book belongs in the cybersecurity canon. But if you are trying to explain some of this stuff to, say, a nongeek boss, this book also might come in very handy. I believe it is canon-worthy material, and you should have read it by now.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For the past decade, I have had this notion that there must be a Cybersecurity Canon: a list of must-read books where the content is timeless, genuinely represents an aspect of the &hellip;<\/p>\n","protected":false},"author":43,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[155,4521],"tags":[251,312,311],"coauthors":[791],"class_list":["post-4623","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-2","category-canon","tag-cybersecurity-canon","tag-mark-bowden","tag-worm"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/4623","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=4623"}],"version-history":[{"count":3,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/4623\/revisions"}],"predecessor-version":[{"id":109942,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/4623\/revisions\/109942"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=4623"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=4623"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=4623"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=4623"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}